Post B5ypgrB4R6eVdpP6uG by bagder@mastodon.social
 (DIR) More posts by bagder@mastodon.social
 (DIR) Post #B5ypgrB4R6eVdpP6uG by bagder@mastodon.social
       0 likes, 0 repeats
       
       AISLE boasts about their AI tooling and CVE-2025-42511:"Our autonomous AI system found another critical vulnerability in the FreeBSD DHCP stack - an unauthenticated remote code execution vulnerability with root privileges.This finding is significant not only because RCE as root is about as severe as it gets, but also because FreeBSD was explicitly included in Anthropic’s Mythos announcement, and Mythos did not identify this issue."
       
 (DIR) Post #B5ypgrUDHvxsbCMOkC by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @bagder hmm but if only AISLE is able to identify that vuln, then how would attackers be able to find it? 🤔
       
 (DIR) Post #B5yq9BQMkkGuXm47Xc by bagder@mastodon.social
       0 likes, 0 repeats
       
       @wolf480pl I believe it only explicitly highlighted that Mythos did not find it. Not that no one can't find it.
       
 (DIR) Post #B5yqbrPoE0HasvTmWO by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @bagder yeah but I think the subtext of this competition and the PR around it seems to be "you should use our tool because it can find vulns nobody else can"And sure, there is an asymmetry in that the defender needs to find all vulns an attacker could potentially find, while the attacker only needs to find onebut I wonder if there's a point after which better ways to find vulns don't actually make  users more secure, and become a protection racket
       
 (DIR) Post #B5yqnxYFEkfROHC6nQ by bagder@mastodon.social
       0 likes, 0 repeats
       
       @wolf480pl of course its marketing from their side but my take-away is rather the thing we already knew: none of these tools find *all* the errors and they all are going to find different issues, probably even depending on who runs and pokes at them for each particular code base
       
 (DIR) Post #B5yrLQstCN6rvBoOYa by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @bagder right, so the question is whether finding and fixing some of the errors makes it more difficult for someone else to find more
       
 (DIR) Post #B5yrZrvfRY7pqyzke0 by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @bagder in other words, is there a bounded number of errors in the code, and do the current ways of finding errors get us anywhere near that bound?
       
 (DIR) Post #B5z3KKi9raZVw72CYq by wronglang@bayes.club
       0 likes, 0 repeats
       
       @wolf480pl @bagder yes